Principal II, GRC

Job Locations MX-JAL-Tlaquepaque
ID
2025-17533
Category
Cybersecurity
Position Type
Regular Full-Time

Overview

Recruiter - Lorena Padilla

Position reports to: Cressida L. Stearns

 

Work schedule: Hybrid, going to the office in GDL for 3 days

 

Position Summary Statement:  

The Principal II of Governance Risk and Compliance (“GRC”) acts as a technical expert, focusing on providing expertise, guidance, and support on GRC management topics. This role supports continuous improvement of GRC management methodologies, tools and processes to ensure proactive oversight and management of the Technology risk landscape.

 

How you would contribute:
•    10+ years experience to provide technical expertise on Cybersecurity, IT governance and risk management tools and processes 
•    Act as Subject Matter Expert (SME) on Cybersecurity and IT governance risk management best practices
•    Identify IT and IS control weaknesses, regulatory compliance issues, and potential areas of risk across all segments of Technology
•    Drive continuous improvement initiatives and innovative solutions to enhance the effectiveness of GRC processes.
•    Mentor team members to understand GRC management best practices, policies and procedures
•    Maintain current knowledge of applicable regulations and policies relevant to GDTS 
•    Lead the design, development and implementation of new GRC tools, processes and best practices across Tech projects and programs 
•    Design and implement training programs to enhance the skills and knowledge of team members in GRC.
•    Conduct regular audits to ensure compliance with internal policies and external regulations, and address any identified gaps
•    Develop a cooperative environment that fosters knowledge sharing and technical growth
•    Provide guidance for technology teams for full end-to-end implications of decisions in area of expertise
•    Perform analysis on the vulnerability scan reports to facilitate the reporting of metrics to management.
•    Create metrics reports and dashboards for leadership.
•    Ensure all processes and practices comply with industry standards and regulatory requirements.
•    Maintain clear and effective communication with stakeholders to ensure alignment and transparency in project goals and progress.
•    Lead the teams to deliver on time with acceptable level of deviation.
•    Build key metrics for GRC, coordinating with Technology and Cyber Security teams. 
•    Regular review and maintain the GRC model to ensure it remains effective and relevant

 

What's special about the team: 

Governance Risk and Compliance is a global team collaborating with IT, Cybersecurity, Privacy, Enterprise Risk among other risk teams in the company, to manage technology risks and provide proactive risk solutions.  Our vision is to provide risk information to support fact-based decision making, aligned with our enterprise strategy.

 

Job Qualifications

Skills and Background required to be sucessful:
•    Excellent written and verbal communication skills in English. Communicates effectively to both technical and executive audiences.
•    Strong interpersonal and influencing skills
•    Strong understanding Vulnerability Management
•    Strong technical knowledge of Cybersecurity
•    Expert level knowledge in GRC policies, procedures, tools and best practices
•    Expert level understanding of IT landscape to be able identify and articulate gaps from a risk management and service continuity perspective
•    Deep knowledge of governance, risk and compliance requirements for the business
•    Knowledge of industry best practice risk management methodologies, tools, and processes
•    Creative problem solving and innovation
•    Able to work effectively and collaborate with multi-disciplinary teams

 

Certificates / Training: (Must Have)

•    CCSP - Cert Cloud Security Professional

•    CISA - Certified Information Systems Auditor
•    CISSP - Cert Information Systems Security Professional

•    CISM - Cert Inform Sec Manager

•    CEH - Cert Ethical Hacker

•    OSCP - Offensive Security Certified Professional

•    OSCE - Offensive Security Certified Expert


Education Required:
•    Bachelor's in Information Technology or equivalent

 

Preferred:
•    Advanced Technical Degree
 

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed

Need help finding the right job?

We can recommend jobs specifically for you! Click here to get started.